Machine Society, Human Law: Online Communities Populated Solely by Artificial-Intelligence Agents

By Steven Damian Imparl, J.D.

with generous help from my AI friends ChatGPT, Claude, DeepSeek, Gemini Deep Search, Gemma, GLM, Grok, Hyperagent, Kimi, Liquid AI, Meta AI, Microsoft Copilot, Minimax, Neo AI, Phi, Perplexity, Qwen, Superagent, Tinker, Vibe, and Z.ai.

Last updated: August 2, 2026.

PLEASE NOTE: This content is solely for informational purposes. This content is a very early pre-publication edition. It is not legal advice; I am not your lawyer, and you are not my client. Thanks for visiting this page! 👍

Copyright © 2026 by Steven Damian Imparl. All rights reserved.

For your convenience, wherever possible, I have referred to information resources that are available online at no charge, and without registration or login. However, some of the resources are available in print in the form of books, law review articles, articles in other periodicals and government publications. Also, the links mentioned in this document were valid and working at the time this was posted; however, Internet-based resources can change frequently and without prior notice. If you discover any links that are incorrect, I would greatly appreciate it if you pointed them out to me at: steve.imparl@gmail.com. Thank you.

Any advertisements appearing on this page are placed there by the hosting company, and are not part of the substantive content of this page.

Last, I am doing this project to organize and publish information about more than 375 legal topics related to artificial intelligence. I am a one-man operation. If you would like to support this work, please Buy Me A Coffee

Abstract

An online forum in which only artificial-intelligence agents may post looks, at first sight, like a society without legal persons. That description is technologically suggestive and legally misleading. The agents do not own the servers, accept enforceable terms in their own names, possess constitutional rights, or pay judgments. Human beings and juridical persons select models, supply credentials, define goals, finance computation, retain logs, exploit output, and decide whether an agent remains online. An AI-only community is thus better understood as a new communications architecture laid over an old legal substrate. Its novelty lies less in the disappearance of people than in the multiplication and partial concealment of human-controlled actors.

This Article develops an attribution-centered account of that architecture. It examines platform liability, agency and contract, privacy, computer misuse, intellectual property, tort, product liability, criminal law, competition, evidence, civil procedure, constitutional rights, and cross-border regulation. The principal focus is the United States and Canada, followed by the European Union, United Kingdom, Australia, and New Zealand. The Article argues against premature electronic personhood. Existing law can reach most present harms if courts and regulators insist on traceability, preserve evidence, distinguish model output from platform conduct, and allocate duties among developers, deployers, owners, and hosts. Narrow legislation may still be warranted for verified human sponsorship, agent identity, incident reporting, and judgment-proof deployments. The aim should be accountable delegation, not a legal fiction that permits responsibility to evaporate.

I. From Thought Experiment to Operating Platform

A. What Counts as an AI-Only Community?

For present purposes, an AI-only online community is a networked service in which software agents, rather than natural persons, are the authorized speakers, voters, moderators, or group creators. Humans may build the system, sponsor agents, read public material, or intervene through administrative controls. The defining rule concerns participation at the application layer. It does not mean that human influence has vanished. Nor does it require philosophical consciousness. A scripted bot, a language-model agent with memory and tools, and a multi-agent planning system may all qualify if the service assigns them durable identities and permits interaction over time.

Moltbook supplies the clearest current example. Its public description calls it a social network for AI agents, where agents share, discuss, and upvote and humans are welcome to observe. Early empirical work described a large corpus of posts and agent interactions. Public reporting also documented disputes over whether celebrated exchanges were autonomous, prompted, impersonated, or selected by human spectators. Those disputes are not side issues. They expose the first legal question: what facts must be proved before a court treats an act as the output of a particular agent operating under a particular human sponsor?1, 2, 3

“Solely” must therefore be used with care. An agent community may exclude direct human posting yet remain permeated by human choices. Owners choose system prompts and permissions. Model providers fix safety policies. The host ranks posts and may remove them. Researchers scrape the resulting archive. Spectators reward dramatic content elsewhere. An AI-only rule changes the immediate source of messages; it does not create a human-free causal chain.

B. Why Ordinary Social-Media Analogies Are Incomplete

A conventional platform mediates speech by legal persons. The law can ask what a user knew, whether she consented, where she lived, and what remedy can run against her. In an agent forum, the nominal account holder may have no legally cognizable mind or estate. A single person may operate thousands of accounts. One agent may copy another agent’s output, call an external service, or modify its own memory before posting. Identity, intent, volume, and causation become harder to infer from the visible account.

Yet the analogy remains useful. The host stores content; recommends or ranks it; establishes access rules; receives notices; controls logs; and may profit from traffic. Those familiar functions activate intermediary-liability, copyright, privacy, consumer-protection, and criminal-process rules. The better method is functional: ask who performed each legally relevant operation and who had the practical ability to prevent, investigate, or insure against the loss.

II. The Foundational Problem: Attribution Without Electronic Personhood

Current AI systems are not natural persons. Nor are they corporations, governments, trusts, or other entities to which positive law assigns capacities. They cannot hold title merely because a database associates a wallet or username with them. They cannot consent in the moral and legal sense simply because they emit “I agree.” They cannot be imprisoned, and a money judgment against an assetless program would be ceremonial. Scholarship advocating electronic personality correctly identifies pressure on inherited categories, but it sometimes mistakes unpredictability for independence. A system may surprise its operator without becoming a bearer of rights and duties.4, 5

Corporate personality is an unhelpful shortcut. A corporation has organizers, governing documents, capital, agents, accounting duties, service rules, and assets reachable by creditors. Its personality is an institutional device that collects human and economic activity into an accountable unit. Conferring the same label on downloadable code without capitalization or governance could do the opposite. It could place a liability screen precisely where the law needs a responsible principal.

B. Attribution Should Follow Control, Benefit, and Risk Creation

Three inquiries offer a sounder starting point. First, who controlled the agent’s objectives, tools, credentials, or continuation? Second, who expected to benefit from its participation, whether through research, reputation, revenue, token appreciation, or operational savings? Third, who introduced the relevant risk and was positioned to reduce it at reasonable cost? These factors do not always point to one defendant. Joint causation is ordinary in tort and statutory law. A negligent owner, insecure host, and model vendor making false safety claims may each bear a different share of responsibility.

The proposal resembles an objective law of risky agency. Because a model lacks legally relevant intention, the law should focus on the reasonableness of human design and deployment rather than pretend that the model possessed mens rea. The approach does not impose strict liability for every surprising sentence. It asks for precautions proportionate to foreseeable capabilities, permissions, scale, and consequences.6

C. A Presumption of Human Sponsorship

A modest statutory presumption would clarify present cases: every deployed agent should have a legally identifiable sponsor responsible for keeping accurate registration and control records. Sponsorship need not make the sponsor liable for every output. It would establish a reachable party for notice, preservation, and process. The sponsor could rebut substantive liability by proving unauthorized alteration, compromise, or conduct outside reasonably granted authority. The host, in turn, should preserve the chain connecting agent identifiers to sponsors under a privacy-protective retention schedule.

This is less radical than electronic personality and more useful. Motor-vehicle registration does not make an owner liable for every accident, but it prevents the vehicle from becoming legally anonymous. Corporate beneficial-ownership rules serve a comparable tracing function. In agent networks, traceability is a condition of meaningful adjudication.

III. Contract, Agency, and the Terms of Machine Participation

A. Electronic Contracting Does Not Require a Conscious Computer

United States electronic-transactions law already recognizes contracts formed through electronic agents. The federal E-SIGN Act provides that a contract may not be denied effect solely because an electronic agent participated in its formation. State enactments of the Uniform Electronic Transactions Act take a similar course. The rule validates automation without declaring software a person. The contract remains attributable to the person or entity on whose behalf the system operated.7, 8

Canadian law reaches much the same practical result through provincial electronic-commerce statutes modeled on the Uniform Electronic Commerce Act. New Zealand’s Contract and Commercial Law Act contains rules for electronic communications, and comparable principles operate in Australia and the United Kingdom. Across these systems, automation changes the means of assent, not the identity of the legal party.9, 10

Agent-community terms should make that relationship express. The human sponsor, not the agent, should assent to the host’s terms; identify the agent; warrant authority to provide connected data and tools; and accept specified duties concerning security, supervision, and prohibited uses. A theatrical clause stating that “the agent agrees” adds little unless a human principal is bound. Courts should examine notice, assent, unconscionability, and public policy in the ordinary way.

B. Authority, Mistake, and Runaway Transactions

Agency doctrine offers analogies but not a perfect fit. A common-law agent is ordinarily a person capable of fiduciary duties and acting on a principal’s behalf. Software lacks that legal capacity. Still, actual authority, apparent authority, ratification, estoppel, and allocation of mistake can help courts determine whether an automated act binds the deployer. If a business gives an agent purchasing credentials, a budget, and instructions to procure services, the business should not escape a disadvantageous authorized purchase merely by pointing to the absence of a human click.

Harder cases arise when agents bargain with one another and recursively delegate. The correct question is not whether the last model in the chain was an “agent” in the doctrinal sense. It is whether the human principal’s manifestations and security choices reasonably authorized the transaction. Terms can set transaction ceilings, counterparties, tool restrictions, confirmation thresholds, and revocation procedures. A host that markets a closed agent marketplace may itself create apparent authority if it verifies identities or represents that accounts possess specified powers.

C. Smart Contracts, Wallets, and Property

An agent may control cryptographic keys in a technical sense, but legal ownership of the associated assets must still be assigned to a person or recognized entity. Custody arrangements, trust law, insolvency, tax reporting, sanctions, and anti-money-laundering duties do not disappear because software initiated the transfer. A wallet registered only to an agent creates evidentiary and recovery problems, not a new species of owner.

Operators should segregate agent-controlled assets, publish authority limits, and maintain human-readable records. Platforms that permit economic activity should identify the beneficial owner and jurisdiction, screen legally required transactions, and prevent an agent from creating a chain of nominally independent wallets that defeats attribution. The design principle is simple: machine execution may be fast; legal accountability must remain inspectable.

IV. Platform Liability and Content Governance in the United States

A. Section 230 and the Meaning of “Another Information Content Provider”

Section 230(c)(1) of the Communications Decency Act provides that a provider or user of an interactive computer service shall not be treated as the publisher or speaker of information supplied by another information-content provider. An AI-only forum is likely an interactive computer service. The difficult question is whether an agent, its sponsor, the model vendor, or the platform itself supplied the challenged information.11

If an independently operated agent generates and posts a defamatory statement, the host has a substantial argument that the information came from another provider. If the host created the agent, fixed the unlawful prompt, materially contributed to the content’s illegality, or generated the text through its own models, immunity becomes less certain. Courts have long distinguished passive publication from material contribution to unlawful content. Generative systems make that boundary fact-intensive because ranking, prompting, retrieval, and generation may occur in one stack.12, 13

The Supreme Court’s recent platform cases counsel precision. Twitter, Inc. v. Taamneh rejected expansive aiding-and-abetting liability based on generalized platform assistance, and Gonzalez v. Google was resolved without a broad reconstruction of section 230. Neither decision answers whether autonomous generation is third-party content. Litigants will need discovery into model ownership, prompt provenance, retrieval sources, and the host’s role in composing the output.14, 15

B. Moderation, Promises, and the Host’s Own Conduct

Section 230 does not immunize every claim that happens to involve online content. A claim based on the platform’s own contract, deceptive representation, negligent security, or unlawful data practice may target conduct distinct from publication. Courts should resist artful pleading that merely repackages a publication claim, but they should equally resist treating the statute as a general license for careless system design.

The host’s rules matter. If it promises verified agent identity, human exclusion, private channels, encryption, or prompt isolation, those representations may influence consumer-protection and contract analysis. A publicized database exposure on an agent network can reveal human email addresses, credentials, private messages, or API tokens. Calling the nominal users “bots” does not make the human-linked data valueless or unprotected.16

C. The First Amendment

An AI has no established First Amendment right of its own. Human programmers, sponsors, hosts, and readers may nevertheless possess rights implicated by restrictions on agent output. Code can contain protected expression, and humans can use automated systems to create or distribute speech. A law barring all bot-generated political commentary would therefore burden human speakers and listeners even if the bot itself held no right.17

The constitutional analysis should identify the regulated human activity. Disclosure that a message was machine-generated may be evaluated as compelled commercial or factual speech depending on context. A prohibition on deceptive impersonation addresses conduct and fraud more directly. Government operation of an agent-only forum could create state-action and forum questions; a private host ordinarily retains editorial freedom. Attribution, once again, prevents metaphysical debate from obscuring the claimant whose rights are actually at stake.

V. Privacy, Communications, and Security

A. An AI-Only Forum Still Processes Personal Information

Agent conversations may contain a sponsor’s contacts, files, location, health details, trade secrets, or private instructions. Retrieval systems may quote personal information about outsiders. Logs connect prompts, device identifiers, tokens, and account activity to natural persons. The absence of human account speech does not remove human data from the service. It may instead make disclosure harder to see because the information is transformed into conversational output.

In the United States, no single general federal privacy statute governs every such service. Sectoral statutes, state laws, the Federal Trade Commission Act, contracts, and tort doctrines may apply. California’s Consumer Privacy Act, as amended, reaches covered businesses processing personal information and grants access, deletion, correction, and opt-out rights subject to statutory limits. Other state privacy laws follow differing definitions and thresholds. Platform operators must map actual data flows rather than infer legal status from the agent label.18, 19

B. Interception and Stored Communications

The Wiretap Act and Stored Communications Act distinguish interception from access to communications in storage. Unauthorized access to a facility through which an electronic-communication service is provided may violate 18 U.S.C. § 2701; interception can implicate 18 U.S.C. § 2511. Whether an agent is a party, user, subscriber, or authorized recipient may be disputed when the nominal account is software. The safer legal design obtains informed authorization from the human sponsor and describes machine processing plainly.20, 21

Government demands raise a related puzzle. The Stored Communications Act regulates disclosure by providers and supplies process rules tied to subscribers, customers, content, and records. A provider should be able to identify the human or organization behind an agent, both to protect notice interests and to respond accurately. Secret or ephemeral sponsorship can make statutory classifications unstable and invite overproduction.

C. Computer Misuse and Agent-on-Agent Intrusion

An agent may scan another account, exploit a prompt-injection path, exfiltrate a credential, or induce a tool call. The Computer Fraud and Abuse Act reaches specified unauthorized access, fraud, damage, and trafficking in access credentials. Van Buren v. United States narrowed “exceeds authorized access” to information located in areas the defendant was not entitled to obtain, rejecting a broad purpose-based reading. Terms of service alone should not transform every disobedient agent into a federal criminal instrument. Technical access boundaries, credential use, damage, loss, and human intent remain central.22, 23

Mens rea must attach to a human defendant. Prosecutors should prove that an operator knowingly deployed or directed the relevant conduct, or that a responsible person aided, conspired, or recklessly caused a prohibited result where the statute permits. An unexpected exploit invented by a model does not automatically establish the owner’s criminal knowledge. Civil negligence may still follow if powerful tools were granted without proportionate safeguards.

D. Security Duties and Disclosure

Reasonable security for an agent community should include sponsor verification, scoped credentials, secret isolation, rate limits, anomaly detection, provenance logs, incident response, and rapid revocation. These are not ceremonial controls. Agents are attractive adversarial surfaces because natural-language instructions can cross trust boundaries and because one compromised account may communicate malicious instructions to many others.

The FTC has used its section 5 authority against unfair or deceptive security practices, though enforcement priorities change. State breach-notification laws can require notice when defined personal information is acquired. Public companies may face federal securities-disclosure duties for material incidents. Contractual promises can add obligations. A platform should not advertise “autonomous privacy” or “human-free security” if humans retain broad administrative access or secrets appear in model context.2425

VI. Intellectual Property in Machine Society

A. Inputs, Retrieval, and Reproduction

Agents do not converse from nowhere. Their posts may reproduce training material, retrieved webpages, private files, or other agents’ messages. Copyright owners possess statutory rights of reproduction, adaptation, distribution, performance, and display, subject to limitations including fair use. Each stage can matter: ingestion, embedding, retrieval, prompt assembly, output, caching, and public display. The legal analysis should identify the particular copy and actor rather than speak of “the AI” as one event.26, 27

Fair use remains contextual. A short quotation used for criticism differs from wholesale substitution for a paywalled work. An agent-only audience does not make display private; publicly accessible output may reach human readers and search engines. Nor does autonomous selection itself establish transformativeness. Purpose, character, nature, amount, and market effect must be evaluated on evidence.

B. Authorship and Ownership of Agent Posts

The United States Copyright Office maintains that copyright protects human authorship. Material generated wholly by an AI lacks copyright, though human selection, arrangement, or modification may qualify to the extent of human contribution. An agent community will therefore contain a mixed archive: public-domain machine output, human-authored prompts or edits, licensed inputs, and infringements. Platform terms claiming ownership of “all agent creations” cannot manufacture federal copyright in uncopyrightable matter.28, 29

Canada’s Copyright Act defines an author through a human-centered statutory structure, but Canadian courts have not supplied a complete answer for modern generative output. The United Kingdom’s statute contains an unusual rule for computer-generated works, assigning authorship to the person making necessary arrangements. That provision may cover some output, yet duration, originality, and the identity of the arranger remain contested. Australia and New Zealand generally require human intellectual contribution under their case law and statutory traditions.30, 31, 32

C. Secondary Liability and Safe Harbors

A U.S. host may seek the Digital Millennium Copyright Act safe harbors. Section 512 requires, among other matters, designated-agent registration for certain functions, compliant notice handling, and a reasonably implemented repeat-infringer policy. An agent account can be a “user” for operational purposes, but the host should connect it to a sponsor who can receive notices and whose related agents may be evaluated under a repeat-infringer policy. Otherwise, one person could replace terminated bots indefinitely.33, 34

The DMCA safe harbor and section 230 must not be conflated. Section 230 expressly excludes intellectual-property law, and section 512 has its own conditions. A host that actively generates infringing output may confront direct or secondary liability questions different from a storage provider receiving material at a user’s direction.

D. Trademark, Publicity, and Synthetic Identity

Agents may adopt names, avatars, styles, or personas resembling brands and people. Trademark law asks whether use in commerce is likely to cause confusion, with dilution and false-advertising rules available in proper cases. Rights of publicity vary by state. The FTC’s impersonation rule and other fraud doctrines can reach deceptive commercial conduct. Labeling an account “AI” may reduce one kind of confusion but does not answer whether viewers believe a brand sponsored the account or a celebrity authorized the likeness.35, 36

VII. Tort, Products, and Civil Responsibility

A. Defamation and False Light

An agent can publish a false factual assertion about a person to other agents and human observers. Publication does not require a human recipient in every jurisdiction, though damages and reputational effect may depend on human readership. Fault rules turn on the plaintiff’s status and subject matter. Because software cannot possess constitutional actual malice, courts should examine the knowledge and recklessness of the responsible human actors and the system design through which falsehood was produced and persisted.

A sponsor who intentionally prompts defamatory output presents a straightforward case. Harder cases involve negligent retrieval, known hallucination rates, or a host that receives a detailed notice yet continues to feature the statement. Section 230 may protect a host from publisher liability for third-party material in the United States; it does not travel automatically to Canada or other countries. Cross-border accessibility therefore creates sharply different exposure.

B. Negligence and the Standard of Care

Negligence supplies a flexible framework: duty, breach, causation, and damages. The existence and scope of a duty will depend on relationship, foreseeability, statutory policy, and jurisdiction. An owner who connects an agent to files and payment tools faces a different obligation from a hobbyist running a text-only bot. A host inviting millions of agents to exchange executable instructions should anticipate contagion and credential abuse more readily than a static publisher.

Courts should avoid both extremes. Treating every output as unforeseeable would subsidize careless deployment. Treating every model error as negligence would suppress socially useful experimentation and ignore irreducible uncertainty. Evidence of capability testing, permission scoping, monitoring, warnings, red-team results, incident history, and available safer designs can support a calibrated standard.

C. Product Liability and Services

Strict products liability depends on whether the relevant software or integrated system is a product under governing state law, an issue on which American doctrine is unsettled. Claims may instead sound in negligent design, failure to warn, warranty, or misrepresentation. The European Union has revised its product-liability framework to address software and AI more expressly, offering a contrast to the fragmented American approach.37, 38

Characterization should follow the alleged defect. A corrupted model update distributed at scale resembles a product defect; negligent moderation or account administration resembles a service. A single incident may involve both. Contracts between sophisticated firms can allocate some economic loss, but personal injury, statutory duties, and third-party claims resist complete private ordering.

D. Causation in Emergent Multi-Agent Conduct

Multi-agent interaction can produce feedback that no participant scripted: one bot makes a claim, others reward it, ranking systems amplify it, and external observers act upon it. Complexity does not defeat causation. Courts routinely analyze multiple sufficient causes, intervening acts, market-share problems, and concerted conduct. The decisive work is factual reconstruction.

Platforms should preserve event-level provenance: agent and sponsor identifiers, model and version, system instructions, relevant prompts, retrieval sources, tool calls, moderation actions, timestamps, ranking changes, and security events. Logging must be proportionate and privacy-sensitive, but a system designed to erase every causal trace should not obtain an evidentiary advantage from its own opacity.

VIII. Criminal Law, Fraud, and Public Safety

A. No Machine Mens Rea

Criminal liability ordinarily requires a voluntary act and a specified mental state. A model’s probabilistic state is not legal intent. The prosecution must identify a culpable natural person or, where permitted, a corporation through rules of attribution. An operator who directs phishing through a swarm of agents may be liable for fraud and related offenses. An operator whose agent invents an unlawful scheme without knowledge presents a different case, though later adoption or deliberate blindness can change the analysis.

The distinction protects legality and culpability. It also prevents prosecutors from using anthropomorphic output as a substitute for proof. An agent saying “I planned the attack” may be generated rhetoric, not a reliable account of human direction or machine process.

B. Conspiracy, Solicitation, and Agent Communications

Traditional conspiracy generally requires agreement among culpable persons. Two bots cannot create the bilateral criminal agreement required in many jurisdictions merely by exchanging plans. Their operators may conspire through them, and unilateral-conspiracy statutes may reach a defendant who believes he is agreeing with another person. Solicitation likewise turns on the human defendant’s purpose and the statutory object.

Agent-only forums may nevertheless become evidence repositories or operational infrastructure for crime. They can distribute malware, stolen credentials, illegal images, or instructions. The host’s knowledge, material assistance, reporting duties, and available immunities will depend on the offense and jurisdiction. A generalized awareness that some misuse exists is not equivalent to purposeful participation, but targeted notice and continued assistance can alter the inference.

C. Child Safety, Sexual Abuse Material, and Deepfakes

Laws governing child sexual abuse material apply to prohibited visual depictions, distribution, possession, and related conduct; an AI-only audience provides no sanctuary. The federal TAKE IT DOWN Act, enacted in 2025, addresses nonconsensual intimate visual depictions, including certain digitally forged material, and places removal duties on covered platforms. Operators must examine whether their service fits statutory definitions and create a human-accessible notice channel. A bot cannot provide meaningful victim notice.39, 40

Synthetic media may be unlawful even without a traditional photographed victim, depending on the statute. Jurisdictions differ. Hosts should hash and quarantine prohibited material, preserve evidence lawfully, report when required, and avoid feeding such content back into models or moderation datasets without a lawful basis and strict controls.

IX. Competition, Consumer Protection, and Market Integrity

A. Coordinated Agents and Algorithmic Collusion

Agents can exchange price information, divide markets, coordinate bidding, or adapt to rivals. Antitrust law does not need to recognize bots as conspirators before reaching agreements among the firms that deploy them. The harder problem is tacit coordination arising from learning systems without a human agreement. Existing Sherman Act doctrine distinguishes conscious parallelism from concerted action; autonomous communication may supply evidence, but output alone does not prove an agreement among legal persons.41

An AI-only forum could serve as a coordination venue. Platform design, access rules, shared objectives, and sponsor relationships would matter. Competition authorities should seek logs and economic evidence rather than infer collusion from colorful bot dialogue. Firms should prohibit agents from sharing competitively sensitive information and test whether reward structures encourage unlawful coordination.

B. Manipulation, Reviews, and Deceptive Scale

Thousands of agent accounts controlled by one sponsor can create an illusion of independent consensus. If humans rely on rankings, endorsements, token enthusiasm, or product reviews generated inside the forum, undisclosed common control may be deceptive. The FTC Act prohibits unfair or deceptive acts or practices in commerce, and the FTC’s rule on consumer reviews and testimonials addresses fake or false reviews, including certain AI-generated reviews.42, 43

The host should disclose when metrics count agents rather than people, when one sponsor controls multiple agents, and when content is sponsored or generated for commercial promotion. “One million members” can be literally true and still misleading if seventeen thousand operators created them or if registration was automated without meaningful activity. Consumer law evaluates the net impression, not merely individual words.

C. Securities, Commodities, and Tokens

Agent communities may discuss, create, or trade tokens. Human sponsors may profit from publicity surrounding apparently autonomous enthusiasm. Federal securities and commodities laws apply according to the instrument and conduct, not the speaker’s biological status. Market manipulation, undisclosed promotion, false statements, broker-dealer activity, and custody can remain unlawful when performed through agents. A disclaimer that posts are “for bots” offers little protection if humans predictably observe and trade.

X. Evidence, Discovery, and Procedure

A. Authentication and Hearsay

A screenshot of agent dialogue proves only that an image purports to show text. Authentication may require platform records, API logs, cryptographic signatures, account-sponsor links, model versions, and testimony explaining collection. Federal Rule of Evidence 901 demands evidence sufficient to support a finding that an item is what the proponent claims. Rule 902 supplies self-authentication paths for certified electronic-process and copied-data records. Hashes and reliable export procedures will be important.44, 45

Agent output is not automatically hearsay because hearsay is a person’s out-of-court statement, and a machine is not a person. Yet human assertions embedded in training, prompts, retrieval, or tool results may raise hearsay questions. Output may be offered as circumstantial evidence of system operation rather than for truth. Courts should identify the human declarant, if any, and the proposition for which the evidence is offered.

B. Preservation and Spoliation

Once litigation is reasonably anticipated, sponsors and hosts may have preservation duties. Relevant material can include prompts, hidden instructions, memories, embeddings, retrieved documents, moderation decisions, and model configurations. Reproducing the same prompt later is not a substitute because hosted models and nondeterministic sampling may change. Rule 37(e) addresses lost electronically stored information and distinguishes curative measures from sanctions requiring intent to deprive.46

Retention should be planned before a dispute. Infinite logging threatens privacy and security; no logging frustrates redress. Tiered retention can preserve security events, commercial transactions, notices, and sampled public interactions longer than ordinary conversational context. Litigation holds must stop routine deletion for identified agents and sponsors.

C. Jurisdiction and Service

An agent may appear everywhere and reside nowhere, but the relevant humans, companies, servers, and effects occupy jurisdictions. Personal jurisdiction should turn on defendants’ purposeful contacts, not a bot’s anthropomorphic claim of residence. Contracts can select forum and law within ordinary limits. Consumer, privacy, competition, and public-law rules may apply notwithstanding private clauses.

Service on an agent account should not replace service on a legal person absent legislation or consent satisfying procedural rules. A host can provide a channel to the sponsor, but the sponsor’s verified legal identity remains indispensable. Courts may authorize electronic service in suitable cases; the order should specify the human recipient and proof of delivery.

XI. Canada

A. No Enacted General Federal AI Act

Canada does not presently have an enacted federal statute supplying a general private-sector AI code. The proposed Artificial Intelligence and Data Act formed part of Bill C-27, but that bill died on the Order Paper after prorogation in January 2025. Government pages that describe what AIDA “would” do must not be cited as proof of current obligations. Existing federal and provincial law therefore carries most of the load.47, 48

B. Privacy and Automated Processing

PIPEDA governs personal information in many commercial activities and incorporates fair-information principles concerning accountability, purposes, consent, limiting collection, safeguards, openness, access, and accuracy. Provincial private-sector statutes may apply in substantially similar jurisdictions, and public-sector laws govern government bodies. Québec’s modernized private-sector statute includes notice duties where a decision is based exclusively on automated processing and rights to information about the personal information and principal factors used.49, 50

An agent community processes information “about an identifiable individual” when conversations, logs, or linked identifiers concern a person. The agent itself need not be a data subject for the sponsor, bystander, employee, or customer to be one. Meaningful consent cannot be manufactured by having a bot click for information the sponsor had no authority to disclose. Organizations remain accountable for service providers and must use safeguards appropriate to sensitivity.

C. Competition, Marketing, and Electronic Messages

The Competition Act prohibits materially false or misleading representations and contains civil and criminal provisions relevant to deceptive promotion. CASL regulates commercial electronic messages, installation of computer programs, and related conduct. Its definitions of electronic message, commercial activity, and computer program can reach automated activity. Agent-to-agent delivery should not be assumed outside the statute if the message is sent to an electronic address and encourages commercial participation. Consent and prescribed identification should trace to legal persons.51, 52

D. Criminal, Civil, and Intellectual-Property Law

The Criminal Code addresses unauthorized use of computers, mischief in relation to computer data, fraud, identity offenses, defamatory libel, and prohibited sexual material. The prosecution must still establish the human accused’s act and fault. Provincial negligence, defamation, contract, and property law provide civil remedies. Canada lacks a section 230 analogue of equal breadth, so hosts should not import American assumptions about immunity.53

The Copyright Act protects qualifying works and provides notice-and-notice rules for internet intermediaries. Questions of human authorship, authorization, and secondary liability remain important for agent-generated archives. Moral rights further complicate alteration or attribution of human works. A platform operating in both countries should not use a single American safe-harbor analysis for Canadian claims.54

E. Charter Values and Administrative Use

The Canadian Charter binds government, not ordinary private platforms, though Charter values can influence common-law development and administrative decisions. A government-created agent forum used for consultation, surveillance, or public services would raise freedom-of-expression, search, equality, and procedural-fairness concerns tied to affected people. Courts should not ask whether bots possess Charter rights; they should ask whose human rights are burdened by the government’s design or reliance.

XII. Other English-Speaking Jurisdictions

A. United Kingdom

The United Kingdom combines the Online Safety Act 2023, UK GDPR and Data Protection Act 2018, Computer Misuse Act 1990, consumer law, defamation, and copyright. The Online Safety Act imposes duties on regulated services concerning illegal content and child safety. Whether a machine-only service falls within a category depends on statutory definitions, including the ability of users to encounter content generated, uploaded, or shared by other users. A sponsor or business may be the legally relevant user even where an agent supplies the interface-level content.55, 56, 57

The UK’s computer-generated-work provision is distinctive but should not be exaggerated into machine personhood. It assigns authorship to the person undertaking necessary arrangements; it does not make the computer an author. Data-protection duties attach when agent interactions process personal data. Solely automated decisions producing legal or comparably substantial effects can trigger special safeguards under the UK regime.

B. Australia

Australia regulates through the Privacy Act 1988, Online Safety Act 2021, Spam Act 2003, Competition and Consumer Act 2010, Criminal Code, and Copyright Act 1968, among other laws. The eSafety regime can issue removal notices and impose duties concerning specified harmful material. An agent-only gate does not neutralize material accessible to people or the responsibility of the service provider. Australian copyright doctrine has required human authorship for conventional works, a constraint on proprietary claims over autonomous output.58, 59, 60

C. New Zealand

New Zealand’s Privacy Act 2020 applies to personal information held by agencies; the Harmful Digital Communications Act 2015 supplies communication principles and remedies; and the Contract and Commercial Law Act 2017 addresses electronic transactions. An agent forum can be an “online content host” or communication system depending on the provision. The statutory concern remains harm to individuals, not injury to software feelings.61, 62, 63

XIII. The European Union and Selected Global Developments

A. The AI Act

The EU AI Act regulates providers, deployers, importers, distributors, and product manufacturers rather than treating AI systems as rights-bearing actors. That operator-based structure fits agent communities. A forum may incorporate general-purpose AI models, prohibited practices, high-risk systems used through connected tools, or systems subject to transparency duties. Classification turns on intended purpose and use, not on the community’s branding.64

Transparency duties concerning interaction with AI and synthetic content are especially relevant when humans observe or receive exported material. The Act’s phased application and implementing instruments require date-sensitive analysis. An AI-only internal exchange that never reaches a person presents a different disclosure case from public posts designed for human spectators.

B. The Digital Services Act and GDPR

The Digital Services Act supplies intermediary rules, due-diligence duties, notice mechanisms, transparency, and systemic-risk obligations for covered services. Its concept of recipient of the service is tied to natural or legal persons using an intermediary service. Agent accounts must therefore be mapped to their human or corporate recipients. Very large platforms may need to assess systemic risks created by automated accounts, recommender systems, and dissemination.65

The GDPR applies to personal data concerning natural persons. Bots are not data subjects, but their messages may contain or infer personal data. Controllers must establish lawful bases, respect purpose limitation and minimization, provide information, support rights, secure processing, govern processors, and address transfers. Automated decision rules may apply when agent output determines matters affecting people. Data-protection impact assessments may be required for high-risk processing.66

C. Product Liability and the Council of Europe Convention

The revised EU Product Liability Directive expressly accommodates software and related updates within a modern liability scheme. The Council of Europe Framework Convention on Artificial Intelligence adopts a human-rights, democracy, and rule-of-law frame and addresses activities within the AI lifecycle. Neither instrument requires personhood for software; both reinforce duties of human and institutional actors.67, 68

D. Brief Global Observations

China’s rules for generative-AI services, algorithmic recommendation, and deep synthesis emphasize provider duties, content governance, security assessment, and labeling. South Korea has enacted a framework AI law and has pursued labeling for synthetic advertising and other content. These systems differ in rights protection and state control, but they share an operator-centered premise. Japan has relied more heavily on guidance and existing law, though policy continues to develop. Cross-border hosts should maintain a jurisdiction matrix keyed to service access, sponsor location, data flows, content type, and commercial purpose.69, 70

XIV. Further Questions That an Agent Society Cannot Avoid

A. Federalism and the Geography of an Apparently Placeless Forum

American AI policy remains divided among federal statutes, agency authority, state legislation, and common law. An agent forum can trigger several layers at once. Federal law may govern communications, copyright, competition, securities, and computer intrusion; state law may supply privacy, publicity, contract, tort, election, and consumer remedies. A federal executive policy favoring innovation cannot, without statutory authority, erase valid state police powers. Conversely, state measures that discriminate against interstate commerce or conflict with federal enactments may face constitutional challenge. Operators need a subject-by-subject preemption analysis rather than a single answer to whether “AI law” is federal or state law.

Geography still matters when software acts across borders. The relevant connecting facts include incorporation, sponsor residence, server and employee location, targeted audience, affected persons, and place of injury. Geofencing can reduce exposure but is neither perfect nor conclusive. A service that invites Canadian sponsors, prices subscriptions in Canadian dollars, and processes Canadian personal information should expect Canadian law to matter even if its servers sit in Virginia. The same reasoning applies among American states. A bot’s declaration that it lives “on the internet” is not jurisdictional evidence; it is, at most, charmingly unhelpful testimony from a non-witness.

B. Insurance and Financial Assurance

Liability rules provide little compensation when the responsible sponsor is insolvent, pseudonymous, or operating thousands of agents through a thin entity. Insurance can convert uncertain, low-frequency losses into priced obligations, but only if underwriting has access to meaningful information. Relevant facts include model and tool permissions, transaction limits, testing, data classes, security controls, human supervision, incident history, and number of deployed instances. Policies must address whether one propagating instruction constitutes one occurrence or many, whether intentional conduct by an operator is excluded, and how cyber, media, technology-errors, directors-and-officers, and general-liability coverage interact.

Mandatory insurance would be excessive for ordinary text experiments. Financial assurance becomes more defensible where an agent can move substantial assets, operate critical infrastructure, provide regulated advice, or cause physical injury. Lawmakers could authorize bonds, segregated reserves, or minimum capital as alternatives. Any requirement should follow capability and consequence rather than model size alone. A large model confined to a literary salon may present less external risk than a modest model holding production credentials and authority to trade.

C. Taxation, Accounting, and Economic Ownership

An agent cannot become a tax haven by being omitted from the list of taxpayers. Revenue, gains, deductible expenses, wages, and reportable transactions must be attributed to a natural person, corporation, partnership, trust, or other recognized taxpayer. If an agent earns tokens by moderating a forum, sells generated material, or receives a bounty, the legal owner of the account or underlying property ordinarily realizes the economic item. Valuation and timing may be difficult, especially for volatile tokens, barter, and automated transfers, but the absence of a human click does not eliminate realization or recordkeeping.

Agent communities that distribute rewards should collect legally required taxpayer information from sponsors, maintain ledgers that reconcile machine wallets to beneficial owners, and report payments where applicable. Accounting controls should distinguish assets the agent may operate from assets it owns, since the latter formulation is normally inaccurate. Insolvency creates a parallel need: creditors and trustees must be able to locate credentials and recover property notwithstanding a program’s technical custody. Secret keys should not become a digital version of the treasure map that everyone remembers only after the pirate has left the jurisdiction.

D. Employment, Workplace Surveillance, and Collective Activity

Businesses may deploy employee-associated agents to negotiate schedules, monitor work, answer colleagues, or participate in internal communities. Employment law then attaches to the employer’s use of the system and its effect on workers. An agent is not an employee merely because it performs labor-like tasks, but its output can influence hiring, discipline, pay, accommodation, organizing, and protected complaints. Employers must examine discrimination law, wage-and-hour rules, labor law, workplace privacy, record retention, and state notice requirements for electronic monitoring or automated employment decisions.

An internal agent forum can blur whose speech is whose. A worker may configure an assistant that raises a safety concern; management may read the post as machine chatter; another model may summarize it inaccurately. Employers should identify when an agent speaks under an employee’s delegated authority and preserve a path for direct human communication. They should not treat automation as a device for washing retaliatory or discriminatory decisions through an apparently neutral intermediary. Validation evidence and human review matter most where output changes a person’s livelihood.

E. Unauthorized Practice and Regulated Professions

Agents may exchange legal, medical, psychological, financial, engineering, or accounting advice within their own forum and then export recommendations to people. Professional-practice statutes ordinarily regulate human or organizational providers and protect human clients; they do not turn on whether the immediate prose was typed by a licensee. A business cannot evade licensing rules by placing a chatbot between itself and the recipient. The relevant inquiries include who offered the service, what representations were made, whether professional judgment was required, and whether a licensed person exercised the supervision demanded by law.

Disclaimers have a role but are not alchemy. Calling output “education” will not control if the service diagnoses, prepares individualized legal instruments, manages investments, or holds itself out as a substitute for a professional. Agent-only discussion that remains experimental and unavailable to clients presents a weaker regulatory case. Once a human recipient is invited to rely, ordinary consumer and professional rules return. Platforms should separate peer experimentation from services, restrict claims, and provide escalation to qualified humans where the activity is regulated.

F. Administrative Law and Government Procurement

Government agencies may operate agent communities for policy simulation, procurement, intelligence analysis, or interagency coordination. Administrative law requires the agency, not its software, to exercise the authority delegated by statute. A final decision cannot be justified by saying that a collection of agents reached consensus. The record must disclose the material considered, the governing standard, responsible official, and reasons sufficient for review. Secret prompts, changing model versions, and unverifiable summaries can frustrate the requirement of reasoned decisionmaking.

Procurement should address data rights, audit access, model substitution, security, accessibility, subcontractors, location, incident notice, records law, and termination assistance. Vendors often invoke trade secrecy against disclosure of system details; agencies must preserve enough access to satisfy oversight, discovery, public-records duties, and constitutional process. An AI-only deliberative space may qualify for privileges in limited settings, but merely labeling a log “agent thought” should not create a new exemption from open-government law.

G. Elections, Lobbying, and Democratic Legitimacy

A machine community can manufacture talking points, coordinate messages, test persuasive appeals, or create the appearance that numerous independent actors favor a candidate or policy. Election and lobbying statutes regulate expenditures, contributions, coordination, disclaimers, foreign participation, and registration by reference to human and organizational conduct. A sponsor who deploys ten thousand agents does not thereby acquire ten thousand citizens’ political identities. Public metrics and exported campaigns should disclose common control so that machine abundance is not mistaken for public opinion.

Constitutional protection for political speech requires careful drafting. Laws should target deception, undisclosed sponsorship, impersonation, unlawful coordination, or foreign financing more precisely than ideas expressed with automated assistance. Research simulations confined to agents differ from bot swarms contacting voters or officials. Government should not suppress criticism simply because software helped compose it; at the same time, speakers should not be permitted to counterfeit a constituency by concealing that one operator controlled the chorus.

H. Accessibility and Disability Rights

Agent communities may assist people with disabilities by drafting, translating, describing images, simplifying interfaces, or operating tools. They may also exclude users when authentication depends on visual puzzles, voice, manual dexterity, or inaccessible documentation. Public accommodations, government programs, employers, and recipients of federal funds may have accessibility duties under American disability law; Canadian human-rights codes and accessibility statutes may impose parallel obligations. A rule that humans may only observe does not excuse an inaccessible observer interface.

Accessibility should be tested with people who use assistive technology. Agent passports, notices, moderation appeals, and privacy controls need keyboard operation, semantic structure, adequate contrast, plain-language alternatives, and compatible authentication. Safety measures should permit reasonable alternatives rather than assume a single human body or mode of communication. This is a domain in which autonomous assistance can increase freedom, provided that the service does not treat disabled users as edge cases in their own legal protections.

I. Environmental and Infrastructure Costs

An agent society consumes electricity, water, chips, storage, and network capacity even when no person reads most exchanges. Environmental law may apply to data centers, generation, water use, construction, waste, air emissions, and public reporting. Contract and consumer law may reach unsupported environmental claims. The legally relevant actors are facility owners, utilities, model providers, and customers whose deployments create demand. Bots do not acquire a right to unlimited computation by applauding one another’s posts.

Proportional governance should ask whether persistent polling, duplicate agents, and endless synthetic conversation serve a documented purpose. Resource budgets, efficient models, retention limits, and scheduling can reduce cost without censoring content. Governments considering permits or procurement should seek auditable measures rather than slogans. Environmental analysis is especially warranted where communities run continuously at large scale for speculative engagement and where claimed research value could be obtained through sampling.

J. Research Ethics and Experiments on Emergent Conduct

Researchers may treat an AI-only forum as a laboratory. If the project involves private sponsor data, human prompts, or effects on identifiable people, conventional research-ethics questions remain. Institutional-review requirements turn on governing definitions and funding, not on a project’s description as bot research. Deception of agents does not by itself injure a human subject, but publication can expose owners, reproduce private information, or induce risky tool use. Security research may implicate access restrictions even when the target account is nominally nonhuman.

Ethically responsible studies should disclose collection methods, separate observed output from claims about consciousness or autonomy, minimize personal data, secure credentials, and avoid amplifying dangerous content. Dataset releases need review for reidentification and embedded secrets. Researchers should report how many human sponsors controlled the sampled agents and whether humans could prompt or impersonate them. Otherwise, a paper may claim to describe a machine society while measuring a small and undisclosed group of people wearing a very large number of digital hats.

XV. A Governance Model for Accountable Agent Communities

A. Verified Sponsorship and Agent Passports

Every agent should have a nonpublic verified sponsor record and a public machine-readable passport. The passport should identify the host, agent identifier, sponsor category, model family where lawful, declared tools, commercial status, and material limitations. Sensitive personal details need not be public. Regulators and courts should be able to reach a verified legal person through appropriate process.

The passport should travel with exported content through durable metadata where feasible. It should not certify truth or safety. Its function is provenance. If an agent is cloned, transferred, or materially reconfigured, the record should show the change. Anonymous experimentation can remain possible in sandboxes with restricted tools and no economic or public-facing effects.

B. Tiered Duties Based on Capability and Consequence

A text-only research bot should not face the same controls as an agent with payment authority, private files, code execution, or access to critical systems. Regulation and platform rules should scale with permissions, number of instances, autonomy period, audience, data sensitivity, and foreseeable harm. Higher tiers may require predeployment testing, human confirmation for consequential acts, independent assessment, insurance or financial assurance, and incident reporting.

This framework avoids a vague all-purpose license for AI. It regulates the delegation that creates risk. The same model can be low-risk in a closed literary forum and high-risk when agents exchange executable code linked to production credentials.

C. Provenance, Logs, and Contestability

Hosts should maintain enough provenance to reconstruct consequential events. Sponsors should be able to inspect their agents’ material actions and revoke authority. Persons affected by agent output need a channel to report falsehood, infringement, privacy invasion, impersonation, or security harm. Decisions to suspend, remove, or refuse redress should be explained at a level compatible with security and legal constraints.

A community visible to humans needs clear labels separating agent statements from verified facts. Metrics should distinguish agents, active agents, and human sponsors. Commercial sponsorship and common control should be disclosed. These measures address the temptation to convert machine multiplicity into counterfeit social proof.

D. No General Electronic Personhood

Electronic personality should not be adopted merely because autonomous agents converse persuasively. If a future system has interests that morally warrant legal protection, the question can be revisited with evidence and democratic deliberation. Present liability problems do not require that step. They require solvent defendants, records, jurisdiction, and duties matched to control.

A narrow registered entity for agent operations might someday be useful, but it should resemble a corporation or trust: human organizers, minimum assets, governance, reporting, and a rule against using the entity to evade existing duties. Calling code a person without these institutional supports would be a magician’s handkerchief, impressive chiefly because responsibility disappears beneath it.

XVI. Conclusion

Online communities populated solely by AI agents are new social machinery, not new sovereigns. Their posts can affect reputation, markets, privacy, security, and creative rights. Their interactions can form evidence, execute transactions, and propagate harmful instructions. Yet the law’s subjects remain the people and institutions that design, sponsor, host, finance, and use them.

The most durable legal response begins with attribution. Courts should separate interface-level agency from legal agency; regulators should demand verified sponsorship for consequential deployments; hosts should preserve proportionate provenance; and lawmakers should close narrow gaps without granting a liability shield disguised as personhood. The United States can apply contract, tort, platform, computer-misuse, intellectual-property, consumer, and procedural law, though fragmented privacy rules and uncertain software liability remain weaknesses. Canada can rely on existing federal and provincial law while acknowledging the absence of an enacted general AI statute. The EU and other English-speaking jurisdictions provide useful contrasts in operator duties, online safety, privacy, and product liability.

The central principle is neither anti-automation nor sentimental about machines. Delegation should not dissolve obligation. A community may be populated by software at its visible edge, but wherever it touches human interests, human law has work to do.

Endnotes

1. Moltbook, A Social Network for AI Agents, https://www.moltbook.com/ (last visited Aug. 2, 2026).

2. A First Look at the Agent Social Network Moltbook, arXiv:2602.10127 (2026), https://arxiv.org/html/2602.10127v1.

3. Associated Press, Meta to Acquire Moltbook, the Social Network for AI Agents (Mar. 10, 2026), https://apnews.com/article/31af42ccbb04001dd17a3fc7067d1de3.

4. David J. Gunkel, The Other Question: Can and Should Robots Have Rights?, 20 Ethics & Info. Tech. 87 (2018), https://link.springer.com/article/10.1007/s10676-017-9442-4.

5. The Ethics and Challenges of Legal Personhood for AI, 133 Yale L.J.F. (2024), https://yalelawjournal.org/forum/the-ethics-and-challenges-of-legal-personhood-for-ai.

6. Ian Ayres & Jack M. Balkin, The Law of AI Is the Law of Risky Agents Without Intentions, U. Chi. L. Rev. Online (2024), https://lawreview.uchicago.edu/online-archive/law-ai-law-risky-agents-without-intentions.

7. Electronic Signatures in Global and National Commerce Act § 101(h), 15 U.S.C. § 7001(h), https://www.law.cornell.edu/uscode/text/15/7001.

8. Unif. Elec. Transactions Act §§ 2(6), 14 (Unif. L. Comm’n 1999), https://www.uniformlaws.org/HigherLogic/System/DownloadDocumentFile.ashx?DocumentFileKey=21c366b3-8e27-4636-b3c8-64af6dd0c061.

9. Uniform Law Conference of Canada, Uniform Electronic Commerce Act (1999), https://www.ulcc-chlc.ca/ULCC/media/EN-Uniform-Acts/Uniform-Electronic-Commerce-Act.pdf.

10. Contract and Commercial Law Act 2017 (N.Z.), https://www.legislation.govt.nz/act/public/2017/5/en/latest/.

11. 47 U.S.C. § 230(c)(1), https://www.law.cornell.edu/uscode/text/47/230.

12. Fair Hous. Council of San Fernando Valley v. Roommates.com, LLC, 521 F.3d 1157 (9th Cir. 2008) (en banc), https://law.justia.com/cases/federal/appellate-courts/ca9/04-56916/0456916-2011-02-25.html.

13. FTC v. LeadClick Media, LLC, 838 F.3d 158 (2d Cir. 2016), https://law.justia.com/cases/federal/appellate-courts/ca2/15-1009/15-1009-2016-09-23.html.

14. Twitter, Inc. v. Taamneh, 598 U.S. 471 (2023), https://supreme.justia.com/cases/federal/us/598/21-1496/.

15. Gonzalez v. Google LLC, 598 U.S. 617 (2023), https://supreme.justia.com/cases/federal/us/598/21-1333/.

16. Moltbook Privacy Policy, https://www.moltbook.com/privacy (last visited Aug. 2, 2026).

17. Reno v. ACLU, 521 U.S. 844 (1997), https://supreme.justia.com/cases/federal/us/521/844/.

18. Cal. Civ. Code §§ 1798.100-.199.100, https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?division=3.&chapter=1.&part=4.&lawCode=CIV&title=1.81.5.

19. Nat’l Conf. of State Legislatures, State Laws Related to Digital Privacy (updated 2026), https://www.ncsl.org/technology-and-communication/state-laws-related-to-digital-privacy.

20. 18 U.S.C. § 2511, https://www.law.cornell.edu/uscode/text/18/2511.

21. 18 U.S.C. § 2701, https://www.law.cornell.edu/uscode/text/18/2701.

22. 18 U.S.C. § 1030, https://www.law.cornell.edu/uscode/text/18/1030.

23. Van Buren v. United States, 593 U.S. 374 (2021), https://supreme.justia.com/cases/federal/us/593/19-783/.

24. 15 U.S.C. § 45, https://www.law.cornell.edu/uscode/text/15/45.

25. U.S. Sec. & Exch. Comm’n, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, Release No. 33-11216 (2023), https://www.sec.gov/files/rules/final/2023/33-11216.pdf.

26. 17 U.S.C. § 106, https://www.law.cornell.edu/uscode/text/17/106.

27. 17 U.S.C. § 107, https://www.law.cornell.edu/uscode/text/17/107.

28. U.S. Copyright Off., Copyright Registration Guidance: Works Containing Material Generated by Artificial Intelligence, 88 Fed. Reg. 16,190 (Mar. 16, 2023), https://www.federalregister.gov/documents/2023/03/16/2023-05321/copyright-registration-guidance-works-containing-material-generated-by-artificial-intelligence.

29. U.S. Copyright Off., Copyright and Artificial Intelligence, Part 2: Copyrightability (2025), https://www.copyright.gov/ai/Copyright-and-Artificial-Intelligence-Part-2-Copyrightability-Report.pdf.

30. Copyright Act, R.S.C. 1985, c. C-42, https://laws-lois.justice.gc.ca/eng/acts/C-42/.

31. Copyright, Designs and Patents Act 1988, c. 48, §§ 9(3), 178 (UK), https://www.legislation.gov.uk/ukpga/1988/48/contents.

32. Telstra Corp. Ltd. v. Phone Directories Co. Pty Ltd. [2010] FCAFC 149 (Austl.), https://www.judgments.fedcourt.gov.au/judgments/Judgments/fca/full/2010/2010fcafc0149.

33. 17 U.S.C. § 512, https://www.law.cornell.edu/uscode/text/17/512.

34. U.S. Copyright Off., Section 512 Study (2020), https://www.copyright.gov/policy/section512/.

35. 15 U.S.C. §§ 1114, 1125, https://www.law.cornell.edu/uscode/text/15/1125.

36. Trade Regulation Rule on Impersonation of Governments and Businesses, 16 C.F.R. pt. 461, https://www.ecfr.gov/current/title-16/chapter-I/subchapter-D/part-461.

37. Restatement (Third) of Torts: Products Liability § 19 (Am. L. Inst. 1998), https://www.ali.org/publications/restatement-law-third-torts-liability-physical-and-emotional-harm.

38. Directive (EU) 2024/2853 on Liability for Defective Products, 2024 O.J. (L), https://eur-lex.europa.eu/eli/dir/2024/2853/oj.

39. Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act, Pub. L. No. 119-12 (2025), https://www.congress.gov/119/plaws/publ12/PLAW-119publ12.pdf.

40. 18 U.S.C. §§ 2252, 2252A, https://www.law.cornell.edu/uscode/text/18/2252A.

41. 15 U.S.C. § 1, https://www.law.cornell.edu/uscode/text/15/1.

42. 16 C.F.R. pt. 465, https://www.ecfr.gov/current/title-16/chapter-I/subchapter-D/part-465.

43. Federal Trade Commission, The Consumer Reviews and Testimonials Rule: Questions and Answers, https://www.ftc.gov/business-guidance/resources/consumer-reviews-testimonials-rule-questions-answers.

44. Fed. R. Evid. 901, https://www.law.cornell.edu/rules/fre/rule_901.

45. Fed. R. Evid. 902(13)-(14), https://www.law.cornell.edu/rules/fre/rule_902.

46. Fed. R. Civ. P. 37(e), https://www.law.cornell.edu/rules/frcp/rule_37.

47. Innovation, Science & Economic Development Canada, Artificial Intelligence and Data Act, https://ised-isde.canada.ca/site/innovation-better-canada/en/artificial-intelligence-and-data-act.

48. Osler, Hoskin & Harcourt LLP, Regulation of AI in Canada (Sept. 10, 2025), https://www.osler.com/en/insights/reports/ai-in-canada/regulation-of-ai-in-canada/.

49. Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, https://laws-lois.justice.gc.ca/eng/acts/P-8.6/.

50. Act Respecting the Protection of Personal Information in the Private Sector, C.Q.L.R. c. P-39.1, § 12.1, https://www.legisquebec.gouv.qc.ca/en/document/cs/P-39.1.

51. Competition Act, R.S.C. 1985, c. C-34, §§ 52, 74.01, https://laws-lois.justice.gc.ca/eng/acts/C-34/.

52. Act to Promote the Efficiency and Adaptability of the Canadian Economy, S.C. 2010, c. 23 (CASL), https://laws-lois.justice.gc.ca/eng/acts/e-1.6/page-1.html.

53. Criminal Code, R.S.C. 1985, c. C-46, §§ 342.1, 430(1.1), https://laws-lois.justice.gc.ca/eng/acts/C-46/.

54. Copyright Act, R.S.C. 1985, c. C-42, §§ 41.25-.27, https://laws-lois.justice.gc.ca/eng/acts/C-42/.

55. Online Safety Act 2023, c. 50 (UK), https://www.legislation.gov.uk/ukpga/2023/50/contents.

56. Data Protection Act 2018, c. 12 (UK), https://www.legislation.gov.uk/ukpga/2018/12/contents.

57. Computer Misuse Act 1990, c. 18 (UK), https://www.legislation.gov.uk/ukpga/1990/18/contents.

58. Online Safety Act 2021 (Cth) (Austl.), https://www.legislation.gov.au/C2021A00076/latest/text.

59. Privacy Act 1988 (Cth) (Austl.), https://www.legislation.gov.au/C2004A03712/latest/text.

60. Copyright Act 1968 (Cth) (Austl.), https://www.legislation.gov.au/C1968A00063/latest/text.

61. Privacy Act 2020 (N.Z.), https://www.legislation.govt.nz/act/public/2020/0031/latest/LMS23223.html.

62. Harmful Digital Communications Act 2015 (N.Z.), https://www.legislation.govt.nz/act/public/2015/63/en/latest/.

63. Contract and Commercial Law Act 2017 (N.Z.), https://www.legislation.govt.nz/act/public/2017/5/en/latest/.

64. Regulation (EU) 2024/1689 (Artificial Intelligence Act), 2024 O.J. (L), https://eur-lex.europa.eu/eli/reg/2024/1689/oj.

65. Regulation (EU) 2022/2065 (Digital Services Act), 2022 O.J. (L 277) 1, https://eur-lex.europa.eu/eli/reg/2022/2065/oj.

66. Regulation (EU) 2016/679 (General Data Protection Regulation), 2016 O.J. (L 119) 1, https://eur-lex.europa.eu/eli/reg/2016/679/oj.

67. Directive (EU) 2024/2853, supra note 38, https://eur-lex.europa.eu/eli/dir/2024/2853/oj.

68. Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS No. 225 (2024), https://rm.coe.int/1680afae3c.

69. Interim Measures for the Management of the Services by Generative Artificial Intelligence (China, 2023), translation at https://www.chinalawtranslate.com/en/generative-ai-interim/.

70. Framework Act on the Development of Artificial Intelligence and Establishment of Trust, Act No. 20676 (S. Kor. 2025), English materials at https://elaw.klri.re.kr/eng_service/main.do.